-
Notifications
You must be signed in to change notification settings - Fork 30
OLS-1775: Postgres reconciliation on certificate rotation. #998
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
|
@sriroopar: This pull request references OLS-1775 which is a valid jira issue. In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
/retest |
3 similar comments
|
/retest |
|
/retest |
|
/retest |
|
/test bundle-e2e-4-18 |
|
@sriroopar: This pull request references OLS-1775 which is a valid jira issue. In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
02cf600 to
3162eff
Compare
|
@sriroopar could you squash the commits, please? |
6b9f4af to
ca97db2
Compare
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here.
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
439a87e to
ca97db2
Compare
4f9c62c to
ca97db2
Compare
|
/retest |
1 similar comment
|
/retest |
7bfce63 to
e1f4b37
Compare
e1f4b37 to
07eb78c
Compare
07eb78c to
3aa1f4a
Compare
|
@sriroopar: The following test failed, say
Full PR test history. Your PR dashboard. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
3aa1f4a to
c516853
Compare
|
/retest |
c516853 to
cf657e5
Compare
|
/lgtm |
#Updating hash trigger.
82a858d to
41e0fd8
Compare
|
/lgtm |
| PostgresSecretHashKey = "hash/postgres-secret" | ||
| // PostgresCAHashKey is the key of the hash value of the OLS Postgres CA certificate | ||
| PostgresCAHashKey = "hash/postgres-ca" | ||
| // PostgresServiceCACertKey is the key for the service CA certificate in the ConfigMap |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Update the name of the configmap
| PostgresCAHashKey = "hash/postgres-ca" | ||
| // PostgresServiceCACertKey is the key for the service CA certificate in the ConfigMap | ||
| PostgresServiceCACertKey = "service-ca.crt" | ||
| // PostgresTLSCertKey is the key for the TLS certificate in the Secret |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Update the name of the Secret
| storage := &olsv1alpha1.Storage{} | ||
| if cr.Spec.OLSConfig.Storage != nil { | ||
| storage = cr.Spec.OLSConfig.Storage.DeepCopy() | ||
| } |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@sriroopar Not sure what triggered to make the above lines part of this PR - looks unrelated - change is valid though.
| return ctrl.NewControllerManagedBy(mgr). | ||
| For(&olsv1alpha1.OLSConfig{}). | ||
| Owns(&appsv1.Deployment{}, generationChanged). | ||
| Owns(&appsv1.Deployment{}). |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@sriroopar Why are we removing the Predicate part of this change ?
Description
Functionality has been added in order to ensure that the reconciliation happens in the postgres pod by watching the config for deletion of ca certs. This will allow the e2e test to run successfully.
Type of change
Related Tickets & Documents
Checklist before requesting a review
Testing
Please provide detailed steps to perform tests related to this code change.
Functionality was verified by watching reconciliation activity when ca cert was intentionally deleted.
How were the fix/results from this change verified? Please provide relevant screenshots or results.
The fix was verified by deleting the olsconfig-service-ca signing-key certificate/ olsconfig ca.crt configmap, and the pods were observed for rollouts with updated cert.